Wing FTP Server 6.0.7 – Unquoted Service Path
# Exploit Title: Wing FTP Server 6.0.7 - Unquoted Service Path
local 相关类别内容索引。Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
# Exploit Title: Wing FTP Server 6.0.7 - Unquoted Service Path
# Exploit Title: FTP Navigator 8.03 - Stack Overflow (SEH)
# Exploit Title: AVS Audio Converter 9.1.2.600 - Stack Overflow (PoC)
# Exploit Title: Prime95 Version 29.8 build 6 - Buffer Overflow (SEH)
# Exploit Title: AVS Audio Converter 9.1 - 'Exit folder' Buffer Overflow
Qualys Security Advisory
Since commit 0fa03c624d8f ("io_uring: add support for sendmsg()", first in v5.3),
# Exploit Title: FTP Commander Pro 8.03 - Local Stack Overflow
# Exploit Title: Inim Electronics Smartliving SmartLAN 6.x - Hard-coded Credentials
# Exploit Title: SpotAuditor 5.3.2 - 'Base64' Local Buffer Overflow (SEH)
Windows 10 UAC bypass for all executable files which are autoelevate true.
// Axel '0vercl0k' Souchet - November 19 2019
# Exploit Title: Trend Micro Deep Security Agent 11 - Arbitrary File Overwrite
#Exploit Title: Amiti Antivirus 25.0.640 - Unquoted Service Path
#Exploit Title: NETGATE Data Backup 3.0.620 - 'NGDatBckpSrv' Unquoted Service Path
# Exploit Title: Microsoft Visual Basic 2010 Express - XML External Entity Injection
# Exploit Title: Microsoft Windows Media Center 2002 - XML External Entity MotW Bypass
# Exploit Title: Microsoft Excel 2016 1901 - XML External Entity Injection
# Exploit Title: Anviz CrossChex 4.3.12 - Local Buffer Overflow
# Exploit Title: Max Secure Anti Virus Plus 19.0.4.020 - Insecure File Permissions
# Exploit Title: Visual Studio 2008 - XML External Entity Injection
# Exploit Title : Bash 5.0 Patch 11 - SUID Priv Drop Exploit
# Exploit Title: TexasSoft CyberPlanet 6.4.131 - 'CCSrvProxy' Unquoted Service Path
# Exploit Title: Microsoft Windows AppXsvc Deployment Extension - Privilege Escalation
# Exploit Title: Easy-Hide-IP 5.0.0.3 - 'EasyRedirect' Unquoted Service Path
# Exploit Title: Waves MaxxAudio Drivers 1.1.6.0 - 'WavesSysSvc64' Unquoted Service Path
Tested on macOS Mojave (10.14.6, 18G87) and Catalina Beta (10.15 Beta 19A536g).
# Exploit Title: LiteManager 4.5.0 - Insecure File Permissions
#Exploit Title: ProShow Producer 9.0.3797 - ('ScsiAccess') Unquoted Service Path
# Exploit Title: GNU Mailutils 3.7 - Local Privilege Escalation
# Exploit Title: Studio 5000 Logix Designer 30.01.00 - 'FactoryTalk Activation Service' Unquoted Service Path
#Exploit Title: BartVPN 1.2.2 - 'BartVPNService' Unquoted Service Path
# Exploit Title: NCP_Secure_Entry_Client 9.2 - Unquoted Service Paths
# Exploit Title: MobileGo 8.5.0 - Insecure File Permissions
# Exploit Title: ASUS HM Com Service 1.00.31 - 'asHMComSvc' Unquoted Service Path
# Exploit Title: Emerson PAC Machine Edition 9.70 Build 8595 - 'FxControlRuntime' Unquoted Service Path
# Exploit Title: Shrew Soft VPN Client 2.2.2 - 'iked' Unquoted Service Path
# Exploit Title: oXygen XML Editor 21.1.1 - XML External Entity Injection
# Exploit Title: ScanGuard Antivirus 2020 - Insecure Folder Permissions
# Exploit Title: Wondershare Application Framework Service - "WsAppService" Unquote Service Path
# Exploit Title: Control Center PRO 6.2.9 - Local Stack Based BufferOverflow (SEH)
# Exploit Title: RTK IIS Codec Service 6.4.10041.133 - 'RtkI2SCodec' Unquote Service Path
# Exploit Title: Alps Pointing-device Controller 8.1202.1711.04 - 'ApHidMonitorService' Unquoted Service Path